CVE Database
Common Vulnerabilities and Exposures
Search & Filter CVEs
Tendenze di Pubblicazione CVE (Ultimi 10 Anni)
Latest CVEs (Latest 50 vulnerabilities)
CVE-2026-100752
Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Real Estate Manager (Free) < 6.7.9 - site/realestatemanager.php builds the ORDER B…
9,3 Critical
Set 28, 2026
CVE-2026-100753
Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Real Estate Manager (Free) < 6.7.9 - The public property-detail page’s “leave a …
5,3 Medium
Set 28, 2026
CVE-2026-101105
A vulnerability was determined in code-projects Matrimonial System 1.0. The affected element is the function processprofile_form of the file /create_…
6,3 Medium
Set 28, 2026
CVE-2026-101108
Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Vehicle Manager (Free) < 6.5.8 - site/vehiclemanager.php reads the order_field and…
9,3 Critical
Set 28, 2026
CVE-2026-101109
Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Vehicle Manager (Free) < 6.5.8 - The public vehicle-detail page (task=view) echoe…
5,3 Medium
Set 28, 2026
CVE-2026-101110
Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Book Library (Free) < 6.4.6 - site/booklibrary.php’s books() function reads the fi…
9,3 Critical
Set 28, 2026
CVE-2026-101111
Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Book Library (Free) < 6.4.6 - The public book-detail page template, site/views/vi…
5,3 Medium
Set 28, 2026
CVE-2026-101131
A vulnerability was identified in deepseek-ai deepseek-harness up to 0.1.5-rc.3. Impacted is an unknown function of the file packages/e2b/e2b/src/ind…
3,3 Low
Set 28, 2026
CVE-2026-101132
A security flaw has been discovered in DeepSeek deepseek-harness up to 0.1.7-rc.2. The affected element is the function loadProfile of the file packa…
3,1 Low
Set 28, 2026
CVE-2026-101139
A vulnerability was detected in Webkul Bagisto up to 2.4.6. This impacts an unknown function of the file /admin/sales/invoices/mass-update/state of t…
2,7 Low
Set 28, 2026
CVE-2026-102010
A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storag…
7,0 High
Set 28, 2026
CVE-2026-13018
Insufficient validation of untrusted input in Codecs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially perform out of …
Set 28, 2026
CVE-2026-84894
In moxygen before commit 004123dd24c3, MoQSession::dataStreamReadLoop keeps using a stream read handle after reading a FIN, which invalidates the han…
Set 28, 2026
CVE-2026-97023
A path traversal vulnerability in Flatpak's handling of the export/bin directory during app deployment allows a malicious Flatpak app to cause deleti…
7,1 High
Set 28, 2026
CVE-2026-97686
Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in the IPNET subsystem failing to properly release allocated kernel me…
5,5 Medium
Set 28, 2026
CVE-2026-96276
If a malicious SDK container declares an extension point with a crafted `directory` path, and a developer runs `flatpak build-init --writable-sdk --s…
6,5 Medium
Set 23, 2026
CVE-2026-101032
navi through 2.24.0 fails to properly escape cheatsheet variable values when substituting them into shell commands. Attackers can inject shell metach…
7,0 High
Set 27, 2026
CVE-2026-101033
KitchenOwl through 0.7.10 fails to verify that category IDs belong to the caller's household in expense and item operations. Authenticated attackers …
4,3 Medium
Set 27, 2026
CVE-2026-101041
The account recovery (password reset) functionality in the vulnerability-lookup web application contains a time-of-check-to-time-of-use (TOCTOU) race…
6,3 Medium
Set 27, 2026
CVE-2026-101042
Parse Server is an open-source backend server. In versions >= 9.0.0 < 9.10.1-alpha.10 and >= 8.0.2 < 8.6.91, the code-based authentication adapters (…
6,4 Medium
Set 27, 2026
CVE-2026-101049
Heym before 0.0.53 fails to verify Slack request signatures when trigger nodes lack credential IDs or have empty signing secrets. Remote unauthentica…
6,5 Medium
Set 27, 2026
CVE-2026-101050
Heym before 0.0.53 fails to verify the X-Telegram-Bot-Api-Secret-Token header on Telegram webhook endpoints when credential_id is absent or secret_to…
6,5 Medium
Set 27, 2026
CVE-2026-88771
Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
This issue affects ADC: before 14.1-73.37, before 13.1…
9,8 Critical
Set 27, 2026
KEV
CVE-2026-88772
Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 …
8,1 High
Set 27, 2026
KEV
CVE-2026-88773
Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
…
10,0 Critical
Set 27, 2026
CVE-2026-88774
Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 …
7,2 High
Set 27, 2026
CVE-2026-88775
Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
This issue affects ADC: before 14.1-73.37, before 13.1-64.23, be…
9,8 Critical
Set 27, 2026
CVE-2026-88776
Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
This issue affects ADC: before 14.1-73.37, before 1…
9,8 Critical
Set 27, 2026
CVE-2026-88777
Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
This issue affects ADC: before 14.1-73.37, before …
9,8 Critical
Set 27, 2026
CVE-2026-88778
Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
This issue affects ADC: before 14.1…
7,5 High
Set 27, 2026
CVE-2026-101043
pnpm versions 11.0.0 before 11.11.0 and 10.7.0 before 10.34.5 expand ${VAR} environment-variable placeholders in the httpProxy, httpsProxy, and noPro…
7,4 High
Set 27, 2026
CVE-2026-101044
pacquet, the Rust package-manager component shipped in the pnpm npm package versions >=12.0.0-alpha.0 and <12.0.0-alpha.5, does not validate dependen…
7,1 High
Set 27, 2026
CVE-2026-101045
Fleet-maintained app install and uninstall scripts for macOS are generated from Homebrew cask metadata. In manifests generated before 2026-08-19, the…
8,0 High
Set 27, 2026
CVE-2026-101046
Fleet before 4.89.0 contains an SQL injection vulnerability in the activity list endpoints (GET /api/v1/fleet/activities and GET /api/v1/fleet/hosts/…
3,1 Low
Set 27, 2026
CVE-2026-101047
Fleet before 4.87.0 does not protect the two endpoints that serve in-house iOS application packages and manifests (enterprise tier only) with the int…
5,3 Medium
Set 27, 2026
CVE-2026-101048
Cloudreve before 4.17.0 registers the administrative node test endpoints (POST /api/v4/admin/node/test and POST /api/v4/admin/node/test/downloader) w…
5,4 Medium
Set 27, 2026
CVE-2026-101051
Cloudreve before 4.16.1 fails to properly sanitize file paths returned by remote downloaders, allowing authenticated users to create files outside th…
3,1 Low
Set 27, 2026
CVE-2026-101056
Cloudreve before 4.16.1 fails to revalidate share access when restoring cached navigator state from a context_hint UUID. Attackers who previously had…
5,3 Medium
Set 27, 2026
CVE-2026-101057
utcp-mcp (the MCP plugin of python-utcp) through 1.1.2 connects to the HTTP and WebSocket MCP server URLs given in a call template's mcpServers confi…
3,1 Low
Set 27, 2026
CVE-2026-101058
python-utcp (pip package utcp-http) before 1.1.12 does not verify whether tool URLs declared in a hand-written UTCP manual point at the agent's own l…
6,9 Medium
Set 27, 2026
CVE-2026-101059
utcp-http before 1.1.4 fails to validate the OAuth2 tokenUrl field from remote OpenAPI specifications, allowing attackers to redirect credential subm…
7,1 High
Set 27, 2026
CVE-2026-101060
python-utcp versions before 1.1.4 contain a server-side request forgery vulnerability in HttpCommunicationProtocol.call_tool that validates the initi…
8,2 High
Set 27, 2026
CVE-2026-101061
utcp-gql before 1.1.1 and utcp-websocket before 1.1.1 contain server-side request forgery vulnerabilities due to incomplete application of CVE-2026-4…
4,7 Medium
Set 27, 2026
CVE-2026-100873
A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. The impacted element is an un…
4,3 Medium
Set 27, 2026
CVE-2026-100874
A flaw has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This affects an unknown function of …
7,3 High
Set 27, 2026
CVE-2026-100875
A vulnerability has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown fun…
7,3 High
Set 27, 2026
CVE-2026-100876
A vulnerability was found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected is an unknown function …
6,3 Medium
Set 27, 2026
CVE-2026-96279
A malicious OCI registry can hardlink arbitrary host files into the extraction directory when a user installs or updates a Flatpak application from a…
6,5 Medium
Set 27, 2026
CVE-2026-100877
A vulnerability was determined in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected by this vulnerabil…
4,3 Medium
Set 27, 2026
CVE-2026-100878
A vulnerability was identified in zhistaredu StarTraining up to 3.8.1. Affected by this issue is the function SysUser.isAdmin of the file edu-common/…
6,3 Medium
Set 27, 2026
CVE ID
CVSS Score
Severity
Date
CVE-2026-100752
9,3
Critical
Set 28, 2026
CVE-2026-100753
5,3
Medium
Set 28, 2026
CVE-2026-101105
6,3
Medium
Set 28, 2026
CVE-2026-101108
9,3
Critical
Set 28, 2026
CVE-2026-101109
5,3
Medium
Set 28, 2026
CVE-2026-101110
9,3
Critical
Set 28, 2026
CVE-2026-101111
5,3
Medium
Set 28, 2026
CVE-2026-101131
3,3
Low
Set 28, 2026
CVE-2026-101132
3,1
Low
Set 28, 2026
CVE-2026-101139
2,7
Low
Set 28, 2026
CVE-2026-102010
7,0
High
Set 28, 2026
CVE-2026-13018
N/A
-
Set 28, 2026
CVE-2026-84894
N/A
-
Set 28, 2026
CVE-2026-97023
7,1
High
Set 28, 2026
CVE-2026-97686
5,5
Medium
Set 28, 2026
CVE-2026-96276
6,5
Medium
Set 23, 2026
CVE-2026-101032
7,0
High
Set 27, 2026
CVE-2026-101033
4,3
Medium
Set 27, 2026
CVE-2026-101041
6,3
Medium
Set 27, 2026
CVE-2026-101042
6,4
Medium
Set 27, 2026
CVE-2026-101049
6,5
Medium
Set 27, 2026
CVE-2026-101050
6,5
Medium
Set 27, 2026
CVE-2026-88771
KEV
9,8
Critical
Set 27, 2026
CVE-2026-88772
KEV
8,1
High
Set 27, 2026
CVE-2026-88773
10,0
Critical
Set 27, 2026
CVE-2026-88774
7,2
High
Set 27, 2026
CVE-2026-88775
9,8
Critical
Set 27, 2026
CVE-2026-88776
9,8
Critical
Set 27, 2026
CVE-2026-88777
9,8
Critical
Set 27, 2026
CVE-2026-88778
7,5
High
Set 27, 2026
CVE-2026-101043
7,4
High
Set 27, 2026
CVE-2026-101044
7,1
High
Set 27, 2026
CVE-2026-101045
8,0
High
Set 27, 2026
CVE-2026-101046
3,1
Low
Set 27, 2026
CVE-2026-101047
5,3
Medium
Set 27, 2026
CVE-2026-101048
5,4
Medium
Set 27, 2026
CVE-2026-101051
3,1
Low
Set 27, 2026
CVE-2026-101056
5,3
Medium
Set 27, 2026
CVE-2026-101057
3,1
Low
Set 27, 2026
CVE-2026-101058
6,9
Medium
Set 27, 2026
CVE-2026-101059
7,1
High
Set 27, 2026
CVE-2026-101060
8,2
High
Set 27, 2026
CVE-2026-101061
4,7
Medium
Set 27, 2026
CVE-2026-100873
4,3
Medium
Set 27, 2026
CVE-2026-100874
7,3
High
Set 27, 2026
CVE-2026-100875
7,3
High
Set 27, 2026
CVE-2026-100876
6,3
Medium
Set 27, 2026
CVE-2026-96279
6,5
Medium
Set 27, 2026
CVE-2026-100877
4,3
Medium
Set 27, 2026
CVE-2026-100878
6,3
Medium
Set 27, 2026